Zephr

Pricing / Corridor

Pricing.Honest.

Local mode is free and shipped. The tier structure above it is settled — Free, Pro, Team, with trust and provenance never behind the paywall. The numbers are not settled, so they are printed here as a planning reference and nothing more. Managed-cloud pricing stays deliberately dark until unit economics pass.

Local mode shipped · Managed cloud plannedADR-021PRODUCT-DESIGN §7no committed prices
The structure

Three tiers. One of them exists today.

The shape of the offer is decided and worth stating plainly. What is not decided is what Pro and Team cost, so each figure below is labelled as the planning input it is — taken from the economics model, not from a price list.

  • Tier / FreeAvailable

    €0

    Available now

    The full local runtime, with no account and no egress. This tier is not a trial of the product — it is the product, running on your machine.

    • Full local mode: evidence graph, eight MCP tools, TrustBench
    • Signed cross-tool handoff (Ed25519), verified on receipt
    • Every trust feature — receipts, abstention, scope binding
    • Limited managed-cloud trial when the cloud opens
    Shipped · local mode
  • Tier / ProNot committed

    ~$19 / dev / mo

    Planning reference · not committed

    One developer, many machines. Adds the hosted spine — cross-device resume, Hosted Lens code intelligence, and managed retention above the local limits.

    • Everything in Free, unchanged and un-gated
    • Cross-device sync and session resume
    • Hosted Lens: lexical, structural, and semantic recall
    • Higher indexed-source and retrieval ceilings
    Planned (managed cloud)
  • Tier / TeamNot committed

    ~$39 / dev / mo

    Planning reference · not committed

    Shared, reviewed memory across a team, with tenancy isolation adversarially tested before any external user exists. The differentiator here is governance, not throughput.

    • Everything in Pro, unchanged and un-gated
    • Team-scoped recall filtered by review state
    • Collaborative review queue and contradiction resolution
    • Organization policy, audit export, and residency controls
    Planned (managed cloud)

Trust is not an upsell. Receipts, abstention, signature verification, and immutable scope binding are in the Free tier and stay there. Paid tiers buy hosting, sharing, and scale — never the ability to tell whether a claim is true.

Figures are planning references from the economics model, not committed pricing.

What you get today

Local mode is free, and it is the whole runtime.

Build from source on your machine and you get the core evidence graph, the eight-tool MCP contract, and the TrustBench deterministic suite. This is the free tier as it actually exists — not a feature-limited preview of something better.

  • Local runtime

    Shipped

    SQLite + sqlite-vec evidence graph, eight MCP tools, and the TrustBench deterministic suite — all running on your machine, with no account and no egress.

    5 indexed sources · 100 daily retrievals · 1 seat

  • Cross-tool continuity

    Shipped

    Handoff packets, session continuity, and adapters for Claude Code and Cursor. Move between agents without re-teaching the project.

    Continuity Format v1 · Ed25519-signed

  • Community support

    Shipped

    Build from source, open GitHub issues, and follow the public docs. No SLA, no ticket queue, no managed backplane.

    Discord / GitHub · no SLA

Free tier: €0. Local limits are 5 indexed sources, 100 daily retrievals, 1 seat. Source: PRICING-AND-METERING.md §1.1.

Feature comparison

What is real, what is in motion, what is only designed.

A comparison table that only says which tier a feature belongs to is half the truth. This one also says whether the feature exists. Six rows are shipped, one is evolving, and four are planned — and the planned rows are listed here rather than quietly omitted.

CapabilityStateFreeProTeam
Local evidence graphShippedFullFullFull
Signed handoff between toolsShippedFullFullFull
Provenance, receipts, abstentionShippedFull — never gatedFull — never gatedFull — never gated
Scope admission and Trust FirewallShippedFull — never gatedFull — never gatedFull — never gated
TrustBench deterministic suiteShippedRuns locallyRuns locallyRuns locally
Revalidation on source changeAnchors shipped · full ref DAG in progressAnchors resolvedAnchors resolvedAnchors resolved
Cross-device syncPlannedNot includedIncludedIncluded
Hosted Lens code intelligencePlannedNot includedIncludedIncluded
Team-scoped shared recallPlannedNot includedNot includedIncluded
Collaborative review queuePlannedNot includedNot includedIncluded
Organization policy and audit exportPlannedNot includedNot includedIncluded

“Not included” on a planned row means two things at once: the capability is not in that tier, and it is not in any tier yet. Both are worth knowing before you plan around it.

Why pricing is dark

We will not sell a price we have not evidenced.

Managed-cloud pricing remains dark because the required evidence is not yet in. Partner pricing is not evidenced. Live Qdrant capacity is not evidenced. The infrastructure costs in the model are planning estimates, not invoices.

The corridor beside this paragraph is an internal reference from UNIT-ECONOMICS.md. It exists to size the next evidence run — how much capacity to buy, how much usage to model, what break-even would have to look like. It is not an offer, a quote, or a promise, and the moment it is treated as one it stops being useful for the thing it was built for.

When the economics gates flip to GO, the price is published together with the evidence that produced it. Until then this page carries no committed prices, and there is nothing here to sign up for.

PRODUCT-DESIGN.md §7 · UNIT-ECONOMICS.md §8 · ADR-021

Corridor / managed cloudNot committed

Planning reference tiers

Free
€0
Pro
~€19/user/mo
Team (5 users)
~€79/mo

Planning reference only. Not committed pricing. These are planning estimates from UNIT-ECONOMICS.md. They must not be represented as committed pricing.

planning inputs · reviewed 2026-07-30
Beta eligibility

Invitation-only, after four gates pass.

Managed-cloud invitations are blocked today. The beta opens only when every gate below has reviewed evidence at the same commit. If any gate is STOP or NOT EVALUATED, the decision is STOP — one green gate does not carry the other three.

Managed beta / scopeBlocked today

What the beta is, and what it is not

  • Auth/tenancy, Postgres graph, and a Qdrant vector index as a derived candidate index.
  • Strict per-installation quotas and abuse controls, enforced rather than advertised.
  • No public signup, no self-serve billing, no SLA/HA promise.
  • Enterprise SSO, multi-region, and GA remain out of scope.
MANAGED-BETA-SCOPE.md
  1. ZEP-231Gate

    Partner readiness

    Cohort demand, trust, provenance, and willingness-to-pay signals pass the readiness rubric.

  2. ZEP-25Gate

    Capacity benchmark

    Live managed/Qdrant capacity evidence and zero-leak hard stop, per the approved benchmark contract.

  3. ZEP-288Gate

    Unit economics

    Measured usage, invoices, provider costs, reservation/settlement evidence, and enforceable limits.

  4. ZEP-1Gate

    Security review

    Current security review green: auth-before-filtering, Postgres reauthorization, and no cross-tenant leak.

No public signup, no self-serve billing. Access is invitation-only, and only after all four gates pass.

When managed cloud ships

Hosted intelligence, team memory, enterprise controls.

These are the planned capabilities that would justify a paid tier. Each one requires evidence before it ships, and none of them takes anything away from local mode — the free runtime keeps working with the network removed.

  • Hosted Lens

    Planned

    Cloud-first code intelligence: lexical, structural, semantic, and repo-graph queries shared across tools and teammates.

    designed in the Lens cluster; not built

  • Team tier

    Planned

    Shared memory, cross-device sync, collaborative review, and team-scoped recall on a managed backplane.

    gated on the ADR-010 tenancy gate

  • SSO + enterprise

    Planned

    Dedicated infrastructure, custom models, SAML/OIDC posture, and negotiated service terms — only after managed cloud is evidenced.

    out of managed-beta scope

All managed-cloud capabilities are planned. No ship date is committed. Source: MANAGED-BETA-SCOPE.md.

Questions

The things people actually ask.

Including the uncomfortable ones. A pricing page that only answers the easy questions is answering a different page's questions.

Can I use Zephr today without paying anything?
Yes. Local mode is the shipped product: clone the repo, build from source, connect a client, and start capturing provenance-backed memories. There is no account, no card, and no egress.
Why is there no price on this page?
Because we have not earned one. Partner pricing is not evidenced, live capacity is not evidenced, and the infrastructure costs in the model are planning estimates rather than invoices. Publishing a number now would be a guess dressed as a commitment.
Are trust and provenance features a paid upgrade?
No, and they will not become one. Receipts, abstention, signature verification, and scope binding are in the free tier permanently. A trust layer that withholds trust behind a paywall is not a trust layer.
What happens to my local data if I later move to the managed cloud?
Nothing is taken away. Local mode keeps working with the network removed, and the evidence card, envelope, and signature formats are identical on both paths — the only thing that changes is where the file lives.
How do I get into the managed beta?
You cannot yet. The beta is invitation-only and opens after all four gates below have reviewed evidence at the same commit. If any gate is STOP or NOT EVALUATED, the decision is STOP.
Will the planning numbers become the real numbers?
Unknown, and we will not pretend otherwise. They exist to size the next evidence run. When the economics gates flip to GO, real pricing is published with the evidence that produced it.

Start with local mode.

Clone the repo, build from source, and run the TrustBench suite on your own machine. Nothing on this page has to resolve before you can use the product.